qimei.dll

Description: 天象

Authors: Copyright (C) 1998 - 2024 Tencent Inc. All rights reserved.

Version: 5.1.2.13

Architecture: 64-bit

Operating System: Windows NT

SHA256: 466b7a3b715de5c7b379a6876a4f506a

File Size: 804.6 KB

Uploaded At: Dec. 4, 2025, 6:18 a.m.

Views: 14

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • a (Ordinal: 1, Address: 0x6799b)
  • a1 (Ordinal: 2, Address: 0x67845)
  • b (Ordinal: 3, Address: 0x679be)
  • c (Ordinal: 4, Address: 0x67abd)
  • d (Ordinal: 5, Address: 0x67b13)
  • e (Ordinal: 6, Address: 0x67c52)
  • z (Ordinal: 7, Address: 0x677f2)

Imported DLLs & Functions

ADVAPI32.dll
  • AddAccessAllowedAceEx (Address: 0x1800a5a20)
  • AddAce (Address: 0x1800a5a28)
  • CloseEventLog (Address: 0x1800a5a30)
  • CloseServiceHandle (Address: 0x1800a5a38)
  • CryptAcquireContextW (Address: 0x1800a5a40)
  • CryptGenRandom (Address: 0x1800a5a48)
  • CryptReleaseContext (Address: 0x1800a5a50)
  • EqualSid (Address: 0x1800a5a58)
  • GetAce (Address: 0x1800a5a60)
  • GetAclInformation (Address: 0x1800a5a68)
  • GetFileSecurityW (Address: 0x1800a5a70)
  • GetLengthSid (Address: 0x1800a5a78)
  • GetSecurityDescriptorControl (Address: 0x1800a5a80)
  • GetSecurityDescriptorDacl (Address: 0x1800a5a88)
  • GetUserNameA (Address: 0x1800a5a90)
  • InitializeAcl (Address: 0x1800a5a98)
  • InitializeSecurityDescriptor (Address: 0x1800a5aa0)
  • LookupAccountNameW (Address: 0x1800a5aa8)
  • OpenEventLogA (Address: 0x1800a5ab0)
  • OpenSCManagerA (Address: 0x1800a5ab8)
  • OpenServiceA (Address: 0x1800a5ac0)
  • QueryServiceStatus (Address: 0x1800a5ac8)
  • ReadEventLogA (Address: 0x1800a5ad0)
  • RegCloseKey (Address: 0x1800a5ad8)
  • RegEnumKeyExA (Address: 0x1800a5ae0)
  • RegOpenKeyExA (Address: 0x1800a5ae8)
  • RegQueryValueExA (Address: 0x1800a5af0)
  • SetFileSecurityW (Address: 0x1800a5af8)
  • SetSecurityDescriptorControl (Address: 0x1800a5b00)
  • SetSecurityDescriptorDacl (Address: 0x1800a5b08)
api-ms-win-crt-convert-l1-1-0.dll
  • atoll (Address: 0x1800a6418)
api-ms-win-crt-filesystem-l1-1-0.dll
  • _access (Address: 0x1800a62c0)
  • _mkdir (Address: 0x1800a62c8)
  • _splitpath_s (Address: 0x1800a62d0)
  • _stat64 (Address: 0x1800a62d8)
  • _wmkdir (Address: 0x1800a62e0)
  • _wsplitpath_s (Address: 0x1800a62e8)
  • _wstat64 (Address: 0x1800a62f0)
api-ms-win-crt-heap-l1-1-0.dll
  • _callnewh (Address: 0x1800a6428)
  • calloc (Address: 0x1800a6430)
  • free (Address: 0x1800a6438)
  • malloc (Address: 0x1800a6440)
api-ms-win-crt-math-l1-1-0.dll
  • ceilf (Address: 0x1800a6468)
  • pow (Address: 0x1800a6470)
api-ms-win-crt-runtime-l1-1-0.dll
  • _beginthreadex (Address: 0x1800a6300)
  • _cexit (Address: 0x1800a6308)
  • _configure_narrow_argv (Address: 0x1800a6310)
  • _crt_atexit (Address: 0x1800a6318)
  • _execute_onexit_table (Address: 0x1800a6320)
  • _initialize_narrow_environment (Address: 0x1800a6328)
  • _initialize_onexit_table (Address: 0x1800a6330)
  • _initterm (Address: 0x1800a6338)
  • _initterm_e (Address: 0x1800a6340)
  • _invalid_parameter_noinfo_noreturn (Address: 0x1800a6348)
  • _register_onexit_function (Address: 0x1800a6350)
  • _seh_filter_dll (Address: 0x1800a6358)
  • terminate (Address: 0x1800a6360)
api-ms-win-crt-stdio-l1-1-0.dll
  • __stdio_common_vsnprintf_s (Address: 0x1800a6268)
  • __stdio_common_vsnwprintf_s (Address: 0x1800a6270)
  • __stdio_common_vsprintf (Address: 0x1800a6278)
  • __stdio_common_vsscanf (Address: 0x1800a6280)
  • __stdio_common_vswscanf (Address: 0x1800a6288)
  • fclose (Address: 0x1800a6290)
  • feof (Address: 0x1800a6298)
  • fgets (Address: 0x1800a62a0)
  • fopen (Address: 0x1800a62a8)
  • fread (Address: 0x1800a62b0)
api-ms-win-crt-string-l1-1-0.dll
  • _stricmp (Address: 0x1800a63a0)
  • _strnicmp (Address: 0x1800a63a8)
  • _strnset_s (Address: 0x1800a63b0)
  • isalnum (Address: 0x1800a63b8)
  • isprint (Address: 0x1800a63c0)
  • isspace (Address: 0x1800a63c8)
  • isxdigit (Address: 0x1800a63d0)
  • strcmp (Address: 0x1800a63d8)
  • strlen (Address: 0x1800a63e0)
  • strncmp (Address: 0x1800a63e8)
  • strncpy_s (Address: 0x1800a63f0)
  • strpbrk (Address: 0x1800a63f8)
  • tolower (Address: 0x1800a6400)
  • wcslen (Address: 0x1800a6408)
api-ms-win-crt-time-l1-1-0.dll
  • _localtime64 (Address: 0x1800a6370)
  • _localtime64_s (Address: 0x1800a6378)
  • _mktime64 (Address: 0x1800a6380)
  • _time64 (Address: 0x1800a6388)
  • strftime (Address: 0x1800a6390)
api-ms-win-crt-utility-l1-1-0.dll
  • rand (Address: 0x1800a6450)
  • srand (Address: 0x1800a6458)
IPHLPAPI.DLL
  • GetBestRoute (Address: 0x1800a60f8)
  • GetIpNetTable (Address: 0x1800a6100)
  • GetNetworkParams (Address: 0x1800a6108)
KERNEL32.dll
  • CloseHandle (Address: 0x1800a5b50)
  • CopyFileW (Address: 0x1800a5b58)
  • CreateDirectoryA (Address: 0x1800a5b60)
  • CreateEventA (Address: 0x1800a5b68)
  • CreateFileA (Address: 0x1800a5b70)
  • CreateFileMappingA (Address: 0x1800a5b78)
  • CreateFileW (Address: 0x1800a5b80)
  • CreateMutexA (Address: 0x1800a5b88)
  • CreateThread (Address: 0x1800a5b90)
  • CreateTimerQueue (Address: 0x1800a5b98)
  • CreateTimerQueueTimer (Address: 0x1800a5ba0)
  • CreateToolhelp32Snapshot (Address: 0x1800a5ba8)
  • DeleteCriticalSection (Address: 0x1800a5bb0)
  • DeleteFileW (Address: 0x1800a5bb8)
  • DeviceIoControl (Address: 0x1800a5bc0)
  • EnterCriticalSection (Address: 0x1800a5bc8)
  • FindClose (Address: 0x1800a5bd0)
  • FindFirstFileW (Address: 0x1800a5bd8)
  • FreeEnvironmentStringsW (Address: 0x1800a5be0)
  • FreeLibrary (Address: 0x1800a5be8)
  • GetComputerNameA (Address: 0x1800a5bf0)
  • GetCurrentProcess (Address: 0x1800a5bf8)
  • GetCurrentProcessId (Address: 0x1800a5c00)
  • GetCurrentThread (Address: 0x1800a5c08)
  • GetCurrentThreadId (Address: 0x1800a5c10)
  • GetDiskFreeSpaceA (Address: 0x1800a5c18)
  • GetDriveTypeA (Address: 0x1800a5c20)
  • GetEnvironmentStringsW (Address: 0x1800a5c28)
  • GetExitCodeThread (Address: 0x1800a5c30)
  • GetFileSize (Address: 0x1800a5c38)
  • GetLastError (Address: 0x1800a5c40)
  • GetLocalTime (Address: 0x1800a5c48)
  • GetLogicalDrives (Address: 0x1800a5c50)
  • GetModuleFileNameA (Address: 0x1800a5c58)
  • GetModuleHandleA (Address: 0x1800a5c60)
  • GetNativeSystemInfo (Address: 0x1800a5c68)
  • GetPrivateProfileIntA (Address: 0x1800a5c70)
  • GetPrivateProfileStringA (Address: 0x1800a5c78)
  • GetProcAddress (Address: 0x1800a5c80)
  • GetProcessHeap (Address: 0x1800a5c88)
  • GetSystemDefaultLCID (Address: 0x1800a5c90)
  • GetSystemDirectoryW (Address: 0x1800a5c98)
  • GetSystemInfo (Address: 0x1800a5ca0)
  • GetSystemTimeAsFileTime (Address: 0x1800a5ca8)
  • GetThreadContext (Address: 0x1800a5cb0)
  • GetTickCount (Address: 0x1800a5cb8)
  • GetTimeZoneInformation (Address: 0x1800a5cc0)
  • GetVersionExA (Address: 0x1800a5cc8)
  • GetVersionExW (Address: 0x1800a5cd0)
  • GlobalMemoryStatusEx (Address: 0x1800a5cd8)
  • HeapAlloc (Address: 0x1800a5ce0)
  • HeapFree (Address: 0x1800a5ce8)
  • InitializeCriticalSection (Address: 0x1800a5cf0)
  • InitializeSListHead (Address: 0x1800a5cf8)
  • IsBadCodePtr (Address: 0x1800a5d00)
  • IsDebuggerPresent (Address: 0x1800a5d08)
  • IsProcessorFeaturePresent (Address: 0x1800a5d10)
  • LeaveCriticalSection (Address: 0x1800a5d18)
  • LoadLibraryA (Address: 0x1800a5d20)
  • LoadLibraryW (Address: 0x1800a5d28)
  • lstrlenW (Address: 0x1800a5e10)
  • MapViewOfFile (Address: 0x1800a5d30)
  • MultiByteToWideChar (Address: 0x1800a5d38)
  • OpenEventA (Address: 0x1800a5d40)
  • OpenFileMappingA (Address: 0x1800a5d48)
  • OpenMutexA (Address: 0x1800a5d50)
  • OpenProcess (Address: 0x1800a5d58)
  • Process32FirstW (Address: 0x1800a5d60)
  • Process32NextW (Address: 0x1800a5d68)
  • QueryDosDeviceA (Address: 0x1800a5d70)
  • QueryPerformanceCounter (Address: 0x1800a5d78)
  • ReadFile (Address: 0x1800a5d80)
  • ResetEvent (Address: 0x1800a5d88)
  • RtlCaptureContext (Address: 0x1800a5d90)
  • RtlLookupFunctionEntry (Address: 0x1800a5d98)
  • RtlVirtualUnwind (Address: 0x1800a5da0)
  • SetEndOfFile (Address: 0x1800a5da8)
  • SetEvent (Address: 0x1800a5db0)
  • SetFilePointer (Address: 0x1800a5db8)
  • SetLastError (Address: 0x1800a5dc0)
  • SetUnhandledExceptionFilter (Address: 0x1800a5dc8)
  • Sleep (Address: 0x1800a5dd0)
  • SwitchToThread (Address: 0x1800a5dd8)
  • TerminateProcess (Address: 0x1800a5de0)
  • UnhandledExceptionFilter (Address: 0x1800a5de8)
  • UnmapViewOfFile (Address: 0x1800a5df0)
  • WaitForSingleObject (Address: 0x1800a5df8)
  • WideCharToMultiByte (Address: 0x1800a5e00)
  • WriteFile (Address: 0x1800a5e08)
MSVCP140.dll
  • _Cnd_broadcast (Address: 0x1800a5f98)
  • _Cnd_destroy_in_situ (Address: 0x1800a5fa0)
  • _Cnd_do_broadcast_at_thread_exit (Address: 0x1800a5fa8)
  • _Cnd_init_in_situ (Address: 0x1800a5fb0)
  • _Cnd_register_at_thread_exit (Address: 0x1800a5fb8)
  • _Cnd_signal (Address: 0x1800a5fc0)
  • _Cnd_timedwait (Address: 0x1800a5fc8)
  • _Cnd_unregister_at_thread_exit (Address: 0x1800a5fd0)
  • _Cnd_wait (Address: 0x1800a5fd8)
  • _Mtx_current_owns (Address: 0x1800a5fe0)
  • _Mtx_destroy_in_situ (Address: 0x1800a5fe8)
  • _Mtx_init_in_situ (Address: 0x1800a5ff0)
  • _Mtx_lock (Address: 0x1800a5ff8)
  • _Mtx_unlock (Address: 0x1800a6000)
  • _Xtime_get_ticks (Address: 0x1800a6008)
  • ?__ExceptionPtrAssign@@YAXPEAXPEBX@Z (Address: 0x1800a5ef8)
  • ?__ExceptionPtrCopy@@YAXPEAXPEBX@Z (Address: 0x1800a5f00)
  • ?__ExceptionPtrCopyException@@YAXPEAXPEBX1@Z (Address: 0x1800a5f08)
  • ?__ExceptionPtrCreate@@YAXPEAX@Z (Address: 0x1800a5f10)
  • ?__ExceptionPtrCurrentException@@YAXPEAX@Z (Address: 0x1800a5f18)
  • ?__ExceptionPtrDestroy@@YAXPEAX@Z (Address: 0x1800a5f20)
  • ?__ExceptionPtrToBool@@YA_NPEBX@Z (Address: 0x1800a5f28)
  • ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ (Address: 0x1800a5ea0)
  • ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ (Address: 0x1800a5ea8)
  • ?_Rethrow_future_exception@std@@YAXVexception_ptr@1@@Z (Address: 0x1800a5eb0)
  • ?_Syserror_map@std@@YAPEBDH@Z (Address: 0x1800a5eb8)
  • ?_Throw_C_error@std@@YAXH@Z (Address: 0x1800a5ec0)
  • ?_Throw_Cpp_error@std@@YAXH@Z (Address: 0x1800a5ec8)
  • ?_Throw_future_error@std@@YAXAEBVerror_code@1@@Z (Address: 0x1800a5ed0)
  • ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ (Address: 0x1800a5ed8)
  • ?_Xbad_function_call@std@@YAXXZ (Address: 0x1800a5ee0)
  • ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x1800a5ee8)
  • ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x1800a5ef0)
  • ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z (Address: 0x1800a5e68)
  • ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z (Address: 0x1800a5e70)
  • ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ (Address: 0x1800a5e78)
  • ??0ios_base@std@@IEAA@XZ (Address: 0x1800a5e80)
  • ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ (Address: 0x1800a5e88)
  • ??1ios_base@std@@UEAA@XZ (Address: 0x1800a5e90)
  • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@I@Z (Address: 0x1800a5e98)
  • ?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z (Address: 0x1800a5f30)
  • ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ (Address: 0x1800a5f38)
  • ?good@ios_base@std@@QEBA_NXZ (Address: 0x1800a5f40)
  • ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z (Address: 0x1800a5f48)
  • ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z (Address: 0x1800a5f50)
  • ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z (Address: 0x1800a5f58)
  • ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ (Address: 0x1800a5f60)
  • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z (Address: 0x1800a5f68)
  • ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ (Address: 0x1800a5f70)
  • ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ (Address: 0x1800a5f78)
  • ?uncaught_exceptions@std@@YAHXZ (Address: 0x1800a5f80)
  • ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z (Address: 0x1800a5f88)
  • ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z (Address: 0x1800a5f90)
NETAPI32.dll
  • NetApiBufferFree (Address: 0x1800a6150)
  • Netbios (Address: 0x1800a6160)
  • NetWkstaUserGetInfo (Address: 0x1800a6158)
ole32.dll
  • CoCreateGuid (Address: 0x1800a5e48)
  • CoInitialize (Address: 0x1800a5e50)
  • CoUninitialize (Address: 0x1800a5e58)
PSAPI.DLL
  • EnumProcessModules (Address: 0x1800a6190)
  • GetModuleFileNameExA (Address: 0x1800a6198)
SHELL32.dll
  • (Address: 0x1800a5e20)
  • SHGetFolderPathA (Address: 0x1800a5e28)
  • SHGetSpecialFolderPathA (Address: 0x1800a5e30)
  • SHGetSpecialFolderPathW (Address: 0x1800a5e38)
SHLWAPI.dll
  • PathAppendA (Address: 0x1800a60d0)
  • PathAppendW (Address: 0x1800a60d8)
  • PathFileExistsA (Address: 0x1800a60e0)
  • StrCmpW (Address: 0x1800a60e8)
USER32.dll
  • GetCursorPos (Address: 0x1800a5b18)
  • GetForegroundWindow (Address: 0x1800a5b20)
  • GetKeyboardLayoutList (Address: 0x1800a5b28)
  • GetKeyboardType (Address: 0x1800a5b30)
  • GetSystemMetrics (Address: 0x1800a5b38)
  • GetWindowTextA (Address: 0x1800a5b40)
VCRUNTIME140_1.dll
  • __CxxFrameHandler4 (Address: 0x1800a6258)
VCRUNTIME140.dll
  • __C_specific_handler (Address: 0x1800a61e8)
  • __CxxFrameHandler3 (Address: 0x1800a61f0)
  • __std_exception_copy (Address: 0x1800a61f8)
  • __std_exception_destroy (Address: 0x1800a6200)
  • __std_terminate (Address: 0x1800a6208)
  • __std_type_info_destroy_list (Address: 0x1800a6210)
  • _CxxThrowException (Address: 0x1800a61e0)
  • _purecall (Address: 0x1800a6218)
  • memchr (Address: 0x1800a6220)
  • memcmp (Address: 0x1800a6228)
  • memcpy (Address: 0x1800a6230)
  • memmove (Address: 0x1800a6238)
  • memset (Address: 0x1800a6240)
  • strstr (Address: 0x1800a6248)
VERSION.dll
  • GetFileVersionInfoA (Address: 0x1800a6170)
  • GetFileVersionInfoSizeA (Address: 0x1800a6178)
  • VerQueryValueA (Address: 0x1800a6180)
WININET.dll
  • HttpOpenRequestA (Address: 0x1800a61a8)
  • HttpSendRequestA (Address: 0x1800a61b0)
  • InternetCloseHandle (Address: 0x1800a61b8)
  • InternetConnectA (Address: 0x1800a61c0)
  • InternetOpenA (Address: 0x1800a61c8)
  • InternetReadFile (Address: 0x1800a61d0)
wlanapi.dll
  • WlanEnumInterfaces (Address: 0x1800a6118)
  • WlanFreeMemory (Address: 0x1800a6120)
  • WlanGetAvailableNetworkList (Address: 0x1800a6128)
  • WlanGetNetworkBssList (Address: 0x1800a6130)
  • WlanOpenHandle (Address: 0x1800a6138)
  • WlanQueryInterface (Address: 0x1800a6140)
WS2_32.dll
  • __WSAFDIsSet (Address: 0x1800a6030)
  • accept (Address: 0x1800a6038)
  • bind (Address: 0x1800a6040)
  • closesocket (Address: 0x1800a6048)
  • connect (Address: 0x1800a6050)
  • freeaddrinfo (Address: 0x1800a6058)
  • getaddrinfo (Address: 0x1800a6060)
  • getsockopt (Address: 0x1800a6068)
  • htonl (Address: 0x1800a6070)
  • htons (Address: 0x1800a6078)
  • inet_addr (Address: 0x1800a6080)
  • inet_ntoa (Address: 0x1800a6088)
  • ioctlsocket (Address: 0x1800a6090)
  • listen (Address: 0x1800a6098)
  • recv (Address: 0x1800a60a0)
  • select (Address: 0x1800a60a8)
  • send (Address: 0x1800a60b0)
  • setsockopt (Address: 0x1800a60b8)
  • socket (Address: 0x1800a60c0)
  • WSACleanup (Address: 0x1800a6018)
  • WSAGetLastError (Address: 0x1800a6020)
  • WSAStartup (Address: 0x1800a6028)